Version 1.0 · Last updated 2026-10-11
Data Processing Agreement
Version 1.0. Effective from the date of publication. Accepted by clicking at signup; the date and version of acceptance are recorded.
This Data Processing Agreement ("DPA") forms part of the Terms of Service between the Customer (the "controller") and Waseem Anjum, trading as Sabbaq, operated from Lahore, Pakistan, serving Dubai/UAE ("Sabbaq", the "processor"). It applies to personal data that Sabbaq processes on the Customer's behalf. It is designed to meet the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021, "PDPL") and, where it applies, Article 28 of the EU General Data Protection Regulation ("GDPR"). If the brokerage is established in the DIFC or ADGM, the DIFC Data Protection Law No. 5 of 2020 or the ADGM Data Protection Regulations 2021 also apply where relevant.
1. Roles
The Customer is the controller and Sabbaq is the processor of Customer Personal Data. Sabbaq is a separate controller for account administration, billing, security and website data, as described in its Privacy Policy.
2. Details of processing (Annex 1)
| Item | Details |
|---|---|
| Subject matter | Providing the Sabbaq WhatsApp AI lead desk |
| Duration | The term of the Terms, plus the deletion period in section 10 |
| Nature and purpose | Receiving and sending WhatsApp messages; receiving portal enquiry emails the Customer forwards to Sabbaq; drafting and sending AI replies; extracting lead details; transcribing voice notes; answering from the Customer's knowledge files; qualifying, routing and handing off leads; SLA alarms; reporting; storing knowledge, listings and settings |
| Data subjects | The Customer's leads (people who message the Customer on WhatsApp); the Customer's agents, managers and other users |
| Categories of data | Name and WhatsApp profile, phone number, message text, voice notes and transcripts, images and documents sent in chat, forwarded portal enquiry emails, qualification answers (budget, area, timeline, property type), routing, hand-off and reply-time records, opt-in and opt-out events; agent names, phone numbers, languages and areas |
| Special categories | None intended. The service is configured not to request them |
3. Instructions
Sabbaq processes Customer Personal Data only on the Customer's documented instructions: these Terms, this DPA and the Customer's configuration of the service. The exception is where the law requires otherwise, in which case Sabbaq will tell the Customer first unless the law forbids it. Sabbaq will tell the Customer if it believes an instruction breaks the PDPL or the GDPR.
4. Confidentiality
Sabbaq ensures that everyone it authorises to process Customer Personal Data is bound by confidentiality.
5. Security (Annex 2)
- Infrastructure: access-controlled infrastructure in the EU. Primary systems (application, database, logs and backups) run on Contabo in France, behind Cloudflare.
- Encryption: secrets (such as WhatsApp access tokens and two-factor secrets) are encrypted with AES-256; data is encrypted in transit (TLS). Passwords are stored only as hashes.
- Workspace isolation: each brokerage's data is logically separated by workspace and enforced on every request.
- Access control: role-based access in the product (owner, manager, agent). The admin panel is protected by Cloudflare Access, and staff access to Customer data is limited to what operating and supporting the service needs.
- Staff access logging: Sabbaq logs admin actions, support access to a Customer workspace (time-limited sessions, with start and end recorded), data exports and deletions, staff views of personal data together with the stated reason, and desk logins with IP address.
- Bot protection: Cloudflare Turnstile.
- Backups: taken daily, stored on Sabbaq's server in the EU (Contabo, France) and kept for about 60 days (14 daily and 8 weekly copies), then deleted.
- Logs: application logs are kept for a limited period, typically up to 30 days; inbound email processing logs are kept for 7 days.
- Trials: during a trial every reply is drafted in shadow mode and approved by an agent before it is sent.
6. Sub-processors
The Customer gives general authorisation for Sabbaq to use sub-processors. The current list is below. Sabbaq will give 30 days' notice by email to the account owner before adding or replacing a sub-processor. If the Customer objects on reasonable data-protection grounds and the parties cannot resolve it, the Customer may terminate the affected service and receive a refund of prepaid fees for the unused period. Sabbaq imposes data-protection obligations on each sub-processor that are substantially the same as this DPA and remains responsible for them.
| Sub-processor | Purpose | Data | Location | Transfer safeguard |
|---|---|---|---|---|
| Contabo | Hosting of the application, database, logs and backups (primary systems) | All Customer Personal Data | European Union (France) | Within the EU |
| Cloudflare | DNS, content delivery and TLS; Access (staff login); Turnstile (bot protection); Email Routing and Workers (inbound portal enquiry emails); cookieless Web Analytics | Data in transit, IP addresses, forwarded enquiry emails | Global network | Cloudflare's DPA, including Standard Contractual Clauses |
| Cloudflare R2 | Storage of knowledge files uploaded by the Customer | Any personal data in uploaded files | Asia-Pacific (APAC) | Cloudflare's DPA, including Standard Contractual Clauses |
| OpenAI | AI replies, lead-detail extraction, knowledge search (embeddings) and voice-note transcription | Message text, voice notes, knowledge file text and related lead details | United States | OpenAI's DPA, including Standard Contractual Clauses. API data is not used for training and may be kept up to 30 days for abuse monitoring |
| Meta Platforms | WhatsApp Business Platform (Cloud API): message transport on the Customer's own WhatsApp Business account | Lead WhatsApp profile, number, messages and media | Meta's global infrastructure | Meta's terms with the Customer |
| Zoho Mail | Business email and support correspondence ([email protected]) | Contact details, email content | United States | Zoho's DPA, including Standard Contractual Clauses |
| Resend | Transactional email (verification, alerts, notifications) | Email address, message content | Japan (Tokyo) | EU adequacy decision for Japan; Resend's DPA |
| Sign in with Google (if the user chooses it) | Name, email, profile image | United States / global | Google's data processing terms, including Standard Contractual Clauses | |
| Paddle | Payments and billing, as merchant of record (collects any VAT due) | Billing contact and payment data | As set out in Paddle's privacy notice | Paddle's terms |
| Payoneer | Receiving invoice payments | Billing contact and payment details | As set out in Payoneer's privacy notice | Payoneer's terms |
7. International transfers
Customer Personal Data may be transferred from the UAE to the EU (Contabo), the United States (OpenAI, Zoho, Google), Japan (Resend), the Asia-Pacific region (Cloudflare R2 knowledge files), through the global networks of Cloudflare and Meta, and to Pakistan (where Sabbaq operates and supports the service). Sabbaq makes these transfers only with the safeguards the law requires:
- UAE PDPL: on the cross-border transfer grounds of the PDPL and its Executive Regulations, using contractual safeguards in each sub-processor's data processing agreement that require an adequate level of protection.
- GDPR, where it applies: an EU adequacy decision where one exists (such as for Japan); otherwise the European Commission's Standard Contractual Clauses (Module 2 or 3, as applicable) included in each provider's data processing terms, or another valid mechanism under GDPR Chapter V.
The Customer may ask for a copy or summary of the relevant safeguards at [email protected].
8. Assistance
- Sabbaq will help the Customer, through the product's features (such as lead and consent CSV exports) or on request by email (such as deletion), to respond to data subjects' requests. It will forward any request it receives directly within 5 business days and will not answer it unless the Customer instructs it to.
- Sabbaq will give reasonable help with security, data protection impact assessments and consultations with authorities.
9. Personal data breaches
Sabbaq will notify the Customer of a personal data breach affecting Customer Personal Data without undue delay and in any case within 72 hours of becoming aware of it. The notice will describe the nature of the breach, the data and people affected (as far as known), likely consequences, and measures taken or proposed. Sabbaq will update the Customer as it learns more.
10. Return and deletion
When the Terms end: the Customer can, for 30 days, export its leads and consent records as CSV from the dashboard and ask Sabbaq by email for a fuller export; the data is then deleted within a further 30 days and removed from backups as they roll off. Sabbaq may keep data only where the law requires it, and then keeps it confidential and limits its use to that purpose.
11. Audits
Sabbaq will make available the information needed to show compliance with this DPA, starting with written answers and documentation. If that is not enough, the Customer may carry out an audit once a year, on at least 30 days' notice, at its own cost, under confidentiality and without disrupting the service.
12. Liability and precedence
Liability under this DPA is subject to the limits in the Terms, as far as the law allows. If this DPA conflicts with the Terms on data protection, this DPA prevails.
13. Contact
Data protection contact: [email protected].